CVE-2023-33206 Information
Aug 09, 2024
cve
Description
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16 4.0.0 SR06 4.1.0 SR04 4.2.0 SR03 and 4.3.0 SR01 fails to validate symlinks during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system’s hard disk.
Reference
https://www.dieboldnixdorf.com/en-us/banking/portfolio/software/security/ https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Matt%20Burch%20-%20Where%E2%80%99s%20the%20Money%20-%20Defeating%20ATM%20Disk%20Encryption-white%20paper.pdf
Share on: